KappAhl's Privacy policy

Published 24 May 2018

As a result of your contact with us at KappAhl, we hold personal information about you. We have reviewed our data processing practices at KappAhl to ensure compliance with the EU’s General Data Protection Regulation (GDPR) that comes into force on 25 May 2018. We explain in our Privacy Policy how we use the information that we hold about you and how we are committed to protecting and respecting your privacy in accordance with the GDPR. It also explains how you can find out what data we hold about you.

General information on the handling of personal data at KappAhl

What is personal data and what is personal data processing?

Any information that can be linked directly or indirectly to a natural, living person is considered personal data. Images (photos) and sound recordings of individuals processed by a computer can also be considered personal data even if no names are given. Encrypted data and various types of electronic identifiers, such as IP numbers, are considered personal data if they can be linked to natural, living persons. All actions taken in connection with personal data are considered to be personal data processing, such as, collection, registration, organization, structuring, storage, processing, alteration, production, reading, usage, disclosure, dissemination or otherwise providing for the, alignment, compilation, restriction, deletion or destruction of said data.

Where does KappAhl retrieve your personal data?

We retrieve certain information from publicly available information services, e.g. we regularly verify your personal identity number against public records to ensure your information is accurate and up-to-date. Information we retrieve from publicly available information services includes names and contact details. We may also collect information regarding your credit rating from credit rating agencies, banks or public records businesses.

Where does KappAhl process your personal data?

Whenever possible, KappAhl processes your personal data within EU and EEA countries (Norway, Iceland and Liechtenstein) as the General Data Protection Regulation indicates that all EU member states must maintain equivalent protection for personal data and personal privacy. As there are no generally-applied regulations to provide an equivalent guarantee for countries outside of the EU and EEA, such a transfer of data may only occur under the following circumstances: Decisions regarding adequate level of protection; Appropriate safeguards, e.g. standard contract clauses or binding company rules, BCRs; Special permission from the Swedish Data Protection Authority; Consent or other specified situations; Transfer on isolated occasions.

Will KappAhl share my information with third parties?

We may share your personal data with either a personal data assistant or an independent personal data management company. We will only share your personal data with a personal data assistant if it is absolutely necessary, and contracts are in place that strictly regulate how your data can be processed. Personal data assistants are required to guarantee the security of the personal data they process and undertake, inter alia, to comply with our security requirements as well as restrictions and requirements regarding the international transfer of personal data. Our personal data assistants assist us with payment solutions, transport, marketing, communications, recruiting and IT services.

Independent personal data management companies may also share your personal information. In that case, we are not the responsible party in terms of how your personal data is processed, rather, the personal data management and privacy policy of the data management company applies. The independent personal data managers we share your data with are government agencies (police, tax authorities, etc.), companies that provide general goods transport and companies offering payment solutions.

Access to, rectification and deletion of your personal data

You are entitled to access information regarding the content of the personal data we process, and you are entitled to request a correction if any information is found to be inaccurate. If you would like to access your registry data more than once a year, we charge a small administrative fee. Under certain circumstances, you may have personal data deleted, for example, if you have not given your consent or you have withdrawn your consent.

Withdrawal of consent

If we process your personal data with your consent, you have the right to withdraw your consent with immediate effect. 

Objection to processing on the grounds of legitimate interests

For personal reasons, you may object to your personal data being processed if processing is based on the concept of legitimate interests, weighing the benefits of processing the data against the privacy risk to the individual. If we are to be able to continue processing your personal data after an objection, we need to be able to prove that we have a reason that outweighs your interests, rights and freedoms.

The right to data portability

You have the right to receive a copy of the personal data which you have provided to us in a structured format. Unlike the right to access registered data, the right to data portability only applies to personal data that you have provided to us and which we process with the support of certain legal grounds, such as a contract with you.

Cookies

A cookie is a small text file that is stored on your computer, mobile phone or device when you visit a website. The cookie helps website providers to recognize your device the next time you visit that website. 

At KappAhl, we use both session cookies (which expire when you close your web browser) and permanent cookies (that remain on your device for a certain amount of time or until you delete them). KappAhl uses cookies to improve our website and your shopping experience.

Examples of the cookies KappAhl collects and stores are:

  • Information regarding a delivery address that the customer has used, ensuring a smoother purchasing experience the next time the customer shops.
  • Information regarding products the visitor has previously viewed, so that these can then appear in a separate category on the product page.
  • Information regarding what products a visitor has favourited, so that these will appear under Favourites (the heart) on their next visit.
  • Information regarding the country the visitor has previously selected, so that the visitor does not have to select that country on their next visit.
  • The customer’s membership card number, to ensure that the customer can collect bonus points on their next purchase.
  • Filter settings the visitor has applied on a category page, so that the visitor does not need to enter these again after viewing each individual product page.
  • Visits to KappAhl’s website for marketing purposes. Cookies mean that our adverts can be shown to visitors interested in our products on websites such as Google and Facebook, and on other partner websites, programmes and e-mails. Cookies make it possible to show adverts based on previous browsing behaviour.
  • User ID in the Google Analytics tool, to improve user experience.

Many web browsers allow you to manage your settings. You can set up your web browser to reject cookies or delete certain cookies.

Please note that if you choose to block cookies, this may negatively affect KappAhl's website or prevent certain parts of it from functioning.

Please note that any changes to cookie or interest-based ad settings must be made on every device (e.g. computer, tablet, etc.) and browser (e.g. Chrome, Explorer, Safari, etc.)

Protection of personal data in KappAhl's system and the management of personal identity numbers

KappAhl has IT systems designed to protect confidentiality, privacy and access to personal data along with well-established procedures for how personal data is processed and who is allowed to do so. Only authorized personnel are permitted to access and process identifying personal data at KappAhl, and we only use that data for the purposes we have reported in our policy document.

Personal identity numbers will only be processed when it is well justified for the purpose, necessary for us to securely verify your identify, to prevent unauthorized access to your data or for another justifiable reason.

Changes to the privacy policy

KappAhl is entitled to make changes to the privacy policy The latest version of the document is always available for review on KappAhl’s website. If changes to the policy are essential to the extent that they are crucial for us to be able to process your personal data, you will receive notice to this effect 30 days in advance on KappAhl’s website and via email (if you have opted to be notified by email). Examples of significant changes are a change in specified purposes or categories of personal data.

 

CUSTOMERS

It is very important to us at KappAhl that you as a customer feel secure in the business you conduct with us and that you understand how and why we process your personal data. We are constantly working to improve your customer experience and our processing of your personal data is a part of that. Below, we have provided details describing what personal data processing entails and for what purpose.

What personal data does KappAhl collect, and what is the purpose as it applies to you as a customer?

We are glad you want to shop with us! Depending on the shopping method or nature of other business you conduct with us, we will need to process your personal information at the time of payment, for delivery of goods or customer service. We only process the personal information that is necessary to better serve you as a customer. Here you can read more about what information we process and why.

Purpose: In order to process your purchase/order

     Processing:

  • Manage your purchase/order of goods
  • (e-commerce/APP; also handling regarding the choice of pickup location, notification and contact info for the ordered goods).
  • Verify that your address is correct with the help of an external cooperating partner
  • Manage tasks for returns or complaint cases.

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • Membership number (members only)
  • Payment information
  • Credit reports from credit information companies
  • Payment history
  • Order and delivery information (e.g. items, quantity, price, discounts, selection of pickup location, order number, package ID)

     When purchases take place in physical stores, no personal data is stored except when you yourself choose to use your membership, e.g. if you claim offers or register the purchase to receive bonuses.

     National ID number (Sweden), date of birth (Norway, Finland, Poland): KappAhl does not store these for purchases, but you may be requested to provide these upon payment of the invoice with KappAhl’s payment providers.

     Legal basis: Implementation of purchase agreement

Purpose: In order to process your customer support case

     Processing:

  • Communicate and answer requests that come in via telephone or digital channels (incl. social media).
  • Keep your identity secure
  • Manage and investigate support case (e.g. membership in Life & Style, e-commerce orders)

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • National ID number (Sweden), date of birth (Norway, Finland, Poland)
  • Customer correspondence (e.g. email, calls)
  • Order and delivery history (e.g. items, quantity, price, discounts, selection of pickup location, order number, package ID)
  • Member information for Life & Style Club (incl. personal settings)
  • Health information provided by you during contact with customer service (e.g. allergies)
  • Technical information about your equipment for support services

     Legal basis: Warranted interest. (The processing of the data is necessary so that we can accommodate your and our interests in managing customer service cases)

Purpose: In order to provide you with relevant information & inspiration

     Processing:

  • Manage your wish to receive information and inspiration via newsletters (not connected to membership in Life & Style)
  • Manage your wish to receive press releases from KappAhl

     Personal data categories:

  • Email address:

     Legal basis: Warranted interest. (The processing of the data is necessary in order to accommodate your interest in receiving relevant information from KappAhl)

Purpose: In order to carry out and manage contests and events

     Processing:

  • Communicating with the participant that takes part in a contest.
  • Communicating with the participant before and after an event (e.g. registration confirmation, questions or evaluations)
  • Manage identification and age verification
  • Name winners and present prizes.

     Personal data categories:

  • Name
  • National ID number or age
  • Contact information (e.g. address, email, cell number)
  • Data provided upon entering contest
  • Data provided upon evaluation of event

Legal basis: Warranted interest. (The processing of the data is necessary in order to accommodate your and our interests in carrying out and managing contests and events.)

Purpose: In order to process the booking of services (e.g. personal shopping)

     Processing:

  • Manage reservations, booking changes and booking cancellations
  • Communication surrounding booking (e.g. send confirmation, reminders)

     Personal data categories:

  • Name
  • Contact information (email address, cell number)
  • Any potential information that you choose to provide

     Legal basis: Implementation of service agreements (the processing of the data is necessary in order to accommodate your and our interests in completing the task)

Purpose: In order to evaluate, develop and improve our services, products and systems for all of our customers

     Processing:

  • To be able to make services more user-friendly, e.g. change the user interface to simplify the flow of information or to highlight features that are often used in our digital media. Analyses to know which payment solutions should be offered to the customers.
  • To be able to develop a groundwork for the purpose of improving the flow of goods and logistics, e.g. by being able to forecast purchases, supply and deliveries.
  • To be able to develop a groundwork for the purpose of developing and improving the company’s range of products.
  • To be able to develop a groundwork for the purpose of developing and improving efficiency of resources from an environmental and sustainability perspective, e.g. by making purchases and planning of deliveries more efficient.
  • To be able to develop a groundwork for the purpose of planning the startup of stores and warehouses.
  • To be able to give customers the possibility of influencing the range of products we provide.
  • To be able to develop a groundwork for the purpose of improving IT systems in order to increase general security for our visitors/customers.
  • In order to meet this end, we perform general analyses in a summarized and organized form, i.e. not on an individual level; for example, regarding:
  • How our websites and digital media are used (e.g. which sites or sections of sites are visited and what searches are made).
  • Purchase history
  • Age
  • Geographical location and/or demographical location.
  • Feedback regarding our services, products and inquiry results.
  • Data from customers’ devices or technical settings.
  • The above personal data is used as a basis for analyses. The results are non-identifying and cannot be linked to you as a person.

     Personal data categories:

  • Purchase and user-generated data (e.g. clicks and search history)
  • Age
  • Place of residence
  • Your correspondence and feedback regarding company services and products
  • Technical data for devices used by the customer and settings, e.g. language settings,
  • IP address, web browser settings, time zone, operating system, screen resolution and platform
  • Information about how you have interacted with us (e.g. how you use the services, login capabilities, when, where)

     Legal basis: Warranted interest. (The processing of the data is necessary in order to accommodate your and our interest in developing and improving our services, products, accessibility, etc.)

Purpose: In order to promote our products and services

     Processing:

  • Display relevant product recommendations, give suggestions, remind you about forgotten/abandoned digital shopping carts in order to simplify future purchases or similar arrangements.
  • Send direct marketing messages via email, SMS, social media or other similar electronic channels for communication, as well as via mail, including offers from collaborators to existing customers outside a loyalty program.
  • In order to understand which type of marketing or direct marketing we should use, we perform analyses, e.g. about:
  • How websites and other digital media are used.
  • Purchase history
  • Age and geographical information
  • Results from inquiries

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • Member information
  • Age
  • Gender
  • Purchase history
  • Customer segment
  • Date of birth
  • Personal choices provided for communication

     Legal basis: For you who are a member in KappAhl Life & Style - Implementation of agreement regarding membership in the loyalty program. (The processing of the data is necessary in order to carry out our commitments according to the agreement regarding membership in the loyalty program. If the information is not provided, our commitments cannot be carried out and you will be denied membership.). Regarding registered and unregistered customer – warranted interest

What personal data does KappAhl collect, and what is the purpose as it applies to you as a KappAhl customer club member?

When you are a member of our Life & Style by KappAhl customer club, our aim is to provide you with the absolute best customer experience, relevant offers, bonuses on all of your purchases and much more. In order for us to accomplish this, we need to process your personal data. Read more about how we process your data and why here.

Purpose: In order to process and administrate your customer account

     Processing: Personal data is processed to create your/the member’s personal pages and administrate the account in order to:

  • Give you authorization to log in to “My Pages” (e.g. via kappahl.com or APP).
  • Keep your identity and age secure.
  • Maintain correct and up-to-date information (e.g. for sending out bonuses, personal offers).
  • Allow us to follow your purchase history
  • Manage your personal settings (e.g. choice of communication)
  •  Analyses are performed to make it possible to develop functions that will simplify your experience.

     Personal data categories:

  •  Name
  • Contact information (e.g. address, email, cell number)
  • National ID number
  • Gender
  • Member information (e.g. date when you registered as a member, member status)
  • Purchase history
  • Address information or cell phone information from external sources (e.g. SPAR, Bisnode)
  • Settings for personal choices in your profile
  • Technical data about computers, cell phones, and other devices used by the member and their settings, e.g. language setting.

Legal basis: Implementation of agreement regarding membership in the loyalty program. (The processing of the data is necessary in order to carry out our commitments according to the agreement regarding membership in the loyalty program. If the information is not provided, our commitments cannot be carried out and you will be denied membership.)

Purpose: In order to process your bonus points

     Processing:

  • Register and calculate your bonus points based on e.g. purchases or personal offers.
  • Administration and communication surrounding your bonus.
  • Manage the disbursement of bonuses via the communication methods provided (e.g. SMS, App)
  • Request/remind of bonus disbursement via SMS

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • National ID number
  • Member information
  • Purchase history

     Legal basis: Implementation of agreement regarding membership in loyalty program. (The processing of the data is necessary in order to carry out our commitments according to the agreement regarding membership in the loyalty program)

Purpose: In order to provide you with member benefits and promotional offers

Processing:

  • In order to provide you with member benefits, general and personal offers, inspiration, invitations to events/club days or other direct marketing.
  • Perform analyses of the data that we collect for the same purpose, e.g. we look at your purchase history, how you use the company website and other digital media, age, where you live, personal selections provided (e.g. communication methods) and results from customer satisfaction or market research inquiries.
  • Based on analyses, our members can participate in different customer groups (customer segments). Therefore, other members can receive different benefits and offers. In order to provide personal offers and communication, analyses are performed on an individual level.

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • Member information (e.g. date of birth, gender)
  • Purchase history
  • Customer segment
  • User-generated information, e.g. visit and click history, based on use of company websites and other services in digital media
  • Customer selections provided regarding products and services
  • Technical data about computers, cell phones, and other devices used by the member and their settings, e.g. language setting
  • Location information from members’ mobile devices, e.g. cell phone or tablet

     Legal basis: Implementation of agreement regarding membership in loyalty program. (The processing of the data is necessary in order to carry out our commitments according to the agreement regarding membership in the loyalty program)

Purpose: To provide you as a member with a personalized shopping experience

     Processing:

  • Give you personalized content as a member.
  • Ask you to tell us how we can improve our service through different types of customer inquiries.
  • Simplify your use of our services (e.g. remind you about forgotten digital shopping carts)
  • Perform analyses of the data we collect in order to give you a personalized experience while using our services.

Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • Member information
  • Age
  • Gender
  • Purchase history
  • Customer segment
  • Date of birth
  • Personal choices provided for communication

Legal basis: For members in KappAhl Life & Style - Implementation of agreement regarding membership in the loyalty program.

Are there other situations where KappAhl may collect personal data about you as a customer?

KappAhl only processes your personal data when necessary. KappAhl needs to process your information in order to manage all the obligations imposed on us and to combat criminal activity and other misuse. You can read more about when and why below. 

Purpose: In order to fulfill the company’s legal obligations

     Processing:

  • To fulfill legal obligations according to requirements by law, verdicts or official decisions. Such requirements can include e.g. requirements regarding product responsibility and product safety such as producing communication and information to the public and customers about product warnings and product recalls, e.g. in the event of a defect or a danger to health, or to the extent that it is required by accounting law or money laundering law and can be ascribed to a single individual.

     Personal data categories:

  • Name
  • Contact information (e.g. address, email, cell number)
  • Your correspondence
  • Information about purchase time, purchase location, faults/complaints about a product
  • National ID number
  • Purchase history
  • Member information (members only)

     Legal basis: Legal obligations

Purpose: In order to prevent misuse of a service or to prevent, avert and investigate criminal activity directed against the company

     Processing:

  • Investigate or prevent fraud or other breaches of law by e.g. incident reporting in stores.
  • Prevent spam mailing, phishing, harassment, attempts at unlawful logins on user accounts or other actions that are forbidden according to a company’s terms of use.
  • Defend and improve the company’s IT environment against attacks and intrusions.

     Personal data categories:

  • Purchase and user-generated data (e.g. clicks and search history)
  • National ID number
  • Video recordings from security cameras
  • Data and settings regarding devices used by customers, e.g. language settings, IP address, web browser settings, time zone, operating system, screen resolution and platform
  • Analyses regarding how customers use the company’s digital services

     Legal basis: Fulfill legal obligations, or alternatively, warranted interest. (The processing of the data is necessary so that we can accommodate our warranted interest in preventing misuse of a service or to prevent, avert or investigate breaches against the company)

How long is my personal data saved?

At KappAhl, we need to store part of your personal data in order to be able to fulfill contractual obligations and meet our legal requirements (accounting, etc.), but also to be able to (for example) address complaints. Your personal data will only be stored for as long as is necessary to fulfill the purposes mentioned. Afterwards, all personal information is deleted, in accordance with KappAhl’s data-cleaning procedures. Personal data in the form of purchase history, which is processed in the framework of KappAhl Life & Style membership, is never stored for longer than 36 months.

Objection to processing of personal data for direct marketing purposes

As a customer, you have the right to opt out of direct marketing. You can notify our customer service department or contact us via our website/app if you do not want us to process your personal data for direct marketing purposes.

Who should I contact if I have questions?

If you have any questions about the processing of your personal data, would like access to your registered data (available free of charge once a year), wish to withdraw your consent, object to processing for purposes of direct marketing etc. you are welcome to contact us. We take these questions seriously so do not hesitate to contact us if you have any questions!

KappAhl Sverige AB, Idrottsvägen 14, Box 303, 431 24 MÖLNDAL, Sweden is the personal data manager responsible for processing the personal data that we collect about you. Please contact KappAhl’s Membership Service at: info@kappahl.com or +46 (0)10-138 87 11. To unsubscribe from SMS messages, text "stopp" to 71450.

If you are not satisfied with how we process and use your personal data, and/or the answers we have given you, you have the right to submit a complaint to the Swedish Data Protection Authority (Datainspektionen) which is the relevant supervisory authority regarding the processing of your personal data.

 

RECRUITMENT

When seeking employment with us at KappAhl, we will need to process your personal data. When you notify us of your interest and submit your application, you give us the right to process your data and keep it until the recruitment process is over or for a reasonable period of time thereafter.

What personal data does KappAhl collect, and what is the purpose as it applies to you taking part in the recruitment process?

Purpose: In order for us to manage the recruitment process

Processing:

  • Applicant registration
  • Receiving and processing resume and cover letter
  • Making a selection from candidates
  • Completion of the recruitment process

Personal data categories:

  • First name & surname
  • Email address
  • Cell phone number
  • Resume
  • Cover letter

Legal basis: Consent to processing of personal data.

How long is my personal data saved?

The information is stored until the process is over or for a reasonable period of time thereafter.

Who should I contact if I have questions?

If you have any questions about the processing of your personal data, would like access to your registered data (available free of charge once a year), wish to withdraw your consent, object to processing for purposes of direct marketing etc., you are welcome to contact us. We take these questions seriously so do not hesitate to contact us if you have any questions!

KappAhl Sverige AB, Idrottsvägen 14, Box 303, 431 24 MÖLNDAL, Sweden is the personal data manager responsible for processing the personal data that we collect about you. Please contact KappAhl’s Membership Service at: info@kappahl.com or +46 (0)10-138 87 11

If you are not satisfied with how we process and use your personal data, and/or the answers we have given you, you have the right to submit a complaint to the Swedish Data Protection Authority (Datainspektionen) which is the relevant supervisory authority regarding the processing of your personal data.

 

OTHER

When you make contact with KappAhl via any channel, whether it is for different types of business activities or other interests, you have the same rights as everyone else. To the extent that KappAhl processes personal data, we record only the personal data that is necessary for justifiable purposes in each respective case and in accordance with all applicable laws.

Rights – how long is my personal data saved?

Processing occurs in accordance with current legislation indicating that personal data shall not be retained for a period of time beyond what is necessary for the purpose of processing said data.

Who should I contact if I have questions?

If you have any questions about the processing of your personal data, would like access to your registered data (available free of charge once a year), wish to withdraw your consent, object to processing for purposes of direct marketing etc. you are welcome to contact us. We take these questions seriously so do not hesitate to contact us if you have any questions!

KappAhl Sverige AB, Idrottsvägen 14, Box 303, 431 24 MÖLNDAL, Sweden is the personal data manager responsible for processing the personal data that we collect about you. You can reach us at +46 31 7715500.

If you are not satisfied with how we process and use your personal data, and/or the answers we have given you, you have the right to submit a complaint to the Swedish Data Protection Authority (Datainspektionen) which is the relevant supervisory authority regarding the processing of your personal data.